Логотип exploitDog
bind:"GHSA-2rvf-329f-p99g" OR bind:"CVE-2016-6794"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-2rvf-329f-p99g" OR bind:"CVE-2016-6794"

Количество 12

Количество 12

github логотип

GHSA-2rvf-329f-p99g

около 3 лет назад

System Property Disclosure in Apache Tomcat

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2016-6794

почти 8 лет назад

When a SecurityManager is configured, a web application's ability to read system properties should be controlled by the SecurityManager. In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70, 6.0.0 to 6.0.45 the system property replacement feature for configuration files could be used by a malicious web application to bypass the SecurityManager and read system properties that should not be visible.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2016-6794

почти 9 лет назад

When a SecurityManager is configured, a web application's ability to read system properties should be controlled by the SecurityManager. In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70, 6.0.0 to 6.0.45 the system property replacement feature for configuration files could be used by a malicious web application to bypass the SecurityManager and read system properties that should not be visible.

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2016-6794

почти 8 лет назад

When a SecurityManager is configured, a web application's ability to read system properties should be controlled by the SecurityManager. In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70, 6.0.0 to 6.0.45 the system property replacement feature for configuration files could be used by a malicious web application to bypass the SecurityManager and read system properties that should not be visible.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2016-6794

почти 8 лет назад

When a SecurityManager is configured, a web application's ability to r ...

CVSS3: 5.3
EPSS: Низкий
oracle-oval логотип

ELSA-2017-2247

около 8 лет назад

ELSA-2017-2247: tomcat security, bug fix, and enhancement update (LOW)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2016:3144-1

больше 8 лет назад

Security update for tomcat

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2016:3129-1

больше 8 лет назад

Security update for tomcat

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2016:3081-1

больше 8 лет назад

Security update for tomcat

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2016:3079-1

больше 8 лет назад

Security update for tomcat

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2017:1632-1

около 8 лет назад

Security update for tomcat6

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2017:1660-1

около 8 лет назад

Security update for tomcat

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2rvf-329f-p99g

System Property Disclosure in Apache Tomcat

CVSS3: 5.3
0%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2016-6794

When a SecurityManager is configured, a web application's ability to read system properties should be controlled by the SecurityManager. In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70, 6.0.0 to 6.0.45 the system property replacement feature for configuration files could be used by a malicious web application to bypass the SecurityManager and read system properties that should not be visible.

CVSS3: 5.3
0%
Низкий
почти 8 лет назад
redhat логотип
CVE-2016-6794

When a SecurityManager is configured, a web application's ability to read system properties should be controlled by the SecurityManager. In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70, 6.0.0 to 6.0.45 the system property replacement feature for configuration files could be used by a malicious web application to bypass the SecurityManager and read system properties that should not be visible.

CVSS3: 3.1
0%
Низкий
почти 9 лет назад
nvd логотип
CVE-2016-6794

When a SecurityManager is configured, a web application's ability to read system properties should be controlled by the SecurityManager. In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70, 6.0.0 to 6.0.45 the system property replacement feature for configuration files could be used by a malicious web application to bypass the SecurityManager and read system properties that should not be visible.

CVSS3: 5.3
0%
Низкий
почти 8 лет назад
debian логотип
CVE-2016-6794

When a SecurityManager is configured, a web application's ability to r ...

CVSS3: 5.3
0%
Низкий
почти 8 лет назад
oracle-oval логотип
ELSA-2017-2247

ELSA-2017-2247: tomcat security, bug fix, and enhancement update (LOW)

около 8 лет назад
suse-cvrf логотип
openSUSE-SU-2016:3144-1

Security update for tomcat

больше 8 лет назад
suse-cvrf логотип
openSUSE-SU-2016:3129-1

Security update for tomcat

больше 8 лет назад
suse-cvrf логотип
SUSE-SU-2016:3081-1

Security update for tomcat

больше 8 лет назад
suse-cvrf логотип
SUSE-SU-2016:3079-1

Security update for tomcat

больше 8 лет назад
suse-cvrf логотип
SUSE-SU-2017:1632-1

Security update for tomcat6

около 8 лет назад
suse-cvrf логотип
SUSE-SU-2017:1660-1

Security update for tomcat

около 8 лет назад

Уязвимостей на страницу